Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


LFD (Local File Disclosure) Exploiting filter_list
Author
Message
RE: LFD (Local File Disclosure) Exploiting #3
(12-19-2013, 05:22 AM)Adorapuff Wrote: Instead of a shitty tutorial, explain why the code is vulnerable and what is going on.

Man,

Not so much to explain, is so simple but, here we go:

1- The developer left the code open to download others files out of the original scope, in this case "download.asp" is vulnerable

2 - We get the index(or another file) with the paths to others that has the credentials to DB, in this case: Includes/connection.asp

3 - With the DB credentials in your hands, you can search for the management site logon users (to defacers), delete tables to (kiddies), upload a shell and creat a backdoor to use as bot, in my case I have access to a .gov web site of my city for own business.. Tongue



Reply





Messages In This Thread
RE: LFD (Local File Disclosure) Exploiting - by kratuspneuma - 12-19-2013, 05:45 AM